This is a pretty typical example of the security posture of microsoft, and yet people continually buy their arguments that open-source and therefore auditable alternatives are inherently less secure than their "trust me bro"